Small program privacy leakage detection method based on abstract syntax tree

By introducing pointer analysis information in real time during the taint analysis process of the mini program, and synchronously processing the relationship between pointer and taint data, the problems of low analysis efficiency and insufficient accuracy in the existing technology are solved, and more efficient and accurate static analysis and privacy leakage detection are achieved.

CN120030538APending Publication Date: 2025-05-23XIDIAN UNIV
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202510075365.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-14
Publication Date
2025-05-23

AI Technical Summary

Technical Problem

The existing static analysis methods of mini programs fail to effectively combine pointer analysis and stain analysis, resulting in low analysis efficiency and insufficient accuracy when facing large mini programs, especially in privacy leakage detection, it is difficult to track the propagation path of sensitive data.

Method used

A method of privacy leakage detection of mini-programs based on abstract syntax tree is proposed. By introducing pointer analysis information in real time during stain analysis, synchronously processing pointer alias relationship and the propagation path of stain data, avoiding redundant calculations and improving analysis efficiency and accuracy.

Benefits of technology

It improves the efficiency and accuracy of static analysis of mini programs, can capture the interaction between pointers and stained data more accurately, and enhances the integrity and accuracy of privacy leakage detection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120030538A_ABST
    Figure CN120030538A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of applet privacy leakage detection methods, and discloses an applet privacy leakage detection method and system based on an abstract syntax tree. Decompiling the packaged file of the applet to obtain a source code file; all the logic layer JavaScript files are converted into AST by using an expression analysis library; obtaining a calling dependency graph between a page logic layer file and a tool file layer according to the file reference relationship, obtaining a field-level binding dependency graph of the page logic layer file and the tool file layer according to a data and event binding relationship of the page rendering layer and the page logic layer, and merging the two layers to obtain a global dependency graph; finally, combining the dependency graphs to generate a global dependency relationship graph; dividing the JavaSript code into a plurality of basic blocks according to the dividing rule of the boundary of the control flow, determining the type of the edge according to the information of the boundary, and obtaining a GCFG by combining the dependency graph; and inputting the GCFG into a taint-pointer analysis module, and obtaining a privacy disclosure path according to predefined sink and source libraries and a data flow propagation rule.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of static detection of privacy leakage of mini-programs, and in particular to a method for detecting privacy leakage of mini-programs based on an abstract syntax tree. Background Art

[0002] Static taint analysis is a static program analysis technology whose core goal is to identify and track the source of untrusted data in the program and track the propagation path of these tainted data in the program. These tainted data usually come from external inputs, such as user input, network data, file reading, etc. Since these data may contain malicious content or unverified information, they may cause serious security issues such as SQL injection, cross-site scripting attacks, buffer overflows, command injection, etc. if they are not fully processed and verified. Static taint analysis statically analyzes program source code, control flow graphs, and data flow graphs to infer how data propagates from the source (such as user input) to other parts of the program, especially sensitive operation areas, to prevent potential vulnerabilities and malicious behavior.

[0003] Mini-programs support ES6 syntax, including modern programming features such as the use of classes, but in existing studies on static analysis of mini-programs, pointer analysis is usually not considered to be introduced into the static analysis of mini-programs. Pointer analysis is an important technology in static program analysis, which can identify the memory address or object pointed to by the pointer variable, and help analyze the memory access mode and potential memory problems of the program. However, considering the characteristics of mini-programs, especially when processing dynamic data and complex control flows, traditional static analysis methods often face efficiency problems, especially when performing pointer analysis and taint analysis. In traditional static analysis, the order of "pointer analysis first, then taint analysis" is usually adopted. Although this method is accurate, when processing large programs, pointer analysis itself consumes a lot of time and computing resources, and when performing taint analysis, it may be necessary to repeatedly analyze the pointer multiple times, which inevitably leads to an increase in time overhead, especially in the case of large mini-programs with strong dynamic characteristics and large amounts of code, the traditional analysis method is less efficient. In response to this problem, the present invention proposes an analysis algorithm combining taint analysis and pointer analysis. This algorithm performs two analysis methods simultaneously, thus avoiding the redundant calculations caused by the traditional method of "first pointer analysis and then taint analysis". Specifically, this method can synchronously process the alias relationship of pointers and the propagation path of taint data by introducing pointer analysis information in real time during the taint analysis process, without the need for multiple repeated analyses. This method not only improves the efficiency of analysis, but also can more accurately capture the interactive relationship between pointers and taint data, thereby improving the accuracy and completeness of static analysis.

[0004] In the development and operation process of mini programs, there are multiple entry points, multiple event triggers, and complex modular features, such as data transfer between pages, event interaction between components, and cross-file calls of tool functions. These features make the control flow of the program highly complex. The traditional control flow generation method based on local or single entry points is difficult to fully and accurately describe the execution logic of the mini program, and it is easy to miss potential interaction paths. The present invention proposes a control flow generation algorithm based on global dependencies. The algorithm first extracts the global dependencies between the tool function layer, the page logic layer, and the page rendering layer by parsing the abstract syntax tree of the code. Then, according to the dependencies and control flow paths, the division rules of Leaders and Terminators are used to divide the program into multiple basic blocks, and the starting point and end point of each basic block are clarified. Finally, by connecting the control flow paths between basic blocks, a control flow graph covering global dependencies is generated, which effectively adapts to the execution characteristics of mini programs with multiple entry points, cross-pages, cross-components, and cross-files.

[0005] Through the above analysis, the problems and defects of the prior art are as follows:

[0006] (1) Pointer analysis is not systematically introduced, which leads to insufficient analysis accuracy when targeting large mini-programs, especially in the detection of privacy leakage issues. Due to the lack of comprehensive analysis of pointers and their data flows, existing methods cannot effectively track how sensitive data propagates in the program through pointers, which in turn affects the discovery of privacy leakage vulnerabilities.

[0007] (2) When processing the control flow generation of small programs, the challenge of insufficient cross-module dependency processing leads to insufficient code coverage of the control flow. Existing methods lack the ability to globally analyze cross-module logical relationships and are also unable to effectively track the complete path of cross-file references, resulting in the omission of inter-module call paths and incomplete control flow graphs, making it impossible to accurately describe the global execution logic of the program. Summary of the invention

[0008] In view of the problems existing in the prior art, the present invention provides a small program privacy leakage detection method based on an abstract syntax tree.

[0009] The present invention is implemented in this way. The method for detecting privacy leakage of small programs based on the abstract syntax tree includes:

[0010] Step 1: Decompile the wxapkg file of the applet to extract the standard applet source code and other complete project files.

[0011] Step 2: Convert each JavaScript file in the logic layer into an abstract syntax tree (AST) to provide a structured representation for subsequent analysis.

[0012] Step 3: Analyze and build the dependencies between the mini program's page rendering layer, page logic layer, layer, and tool function layer.

[0013] Step 4: Based on the basic block generation rules, perform node analysis on each AST, and build the global control flow graph (GCFG) of the applet in combination with the global dependency graph (GDG).

[0014] Step 5: Based on GCFG, according to the data flow analysis rules for the applet and the customized sink & source library, the taint-pointer synchronization analysis algorithm is executed to generate the global data flow graph (GDFG).

[0015] Furthermore, in step one, by decompiling the wxapkg file, the applet source code and other project files obtained include JavaScript code of the logic layer, WXML files of the rendering layer, style sheet WXSS files, and configuration files.

[0016] Furthermore, in step 2, all valid page logic layer file paths are obtained from the app.json file, and each page logic and tool function layer file is traversed one by one, and the esprima library is used to convert it into an abstract syntax tree for each page logic and tool function layer file.

[0017] Furthermore, in step 3, based on the WXML tags and AST nodes, a data and event binding dependency graph between the rendering layer and the page logic layer, and a call dependency graph between the tool function layer itself and the logic layer are established, and the above two are combined to obtain a global dependency graph;

[0018] Furthermore, in step 4, the AST is traversed using a depth-first traversal method. Based on the designed control flow basic block boundary division rules, the boundaries of each basic block are obtained. The control flow generator divides the JavaScript source code into multiple basic blocks and generates the edges of the control flow graph according to the AST node type of the basic block boundary. The initial CFG structure can be generated with only one traversal. Each basic block represents a continuous piece of code logic, and the edges of the control flow graph describe the execution order and jump relationship between these basic blocks. Finally, the generator combines the dependencies in the code to build a global control flow graph for the applet.

[0019] Furthermore, in step five, the constructed GCFG is input into the synchronization analysis module to execute the taint and pointer joint analysis algorithm. To better illustrate and implement the algorithm, the source is broadly defined as two types: taint source (TS) and pointer source (PS). TS comes from the user input and the applet API that returns sensitive information, PS comes from the introduction of new objects, and the sink is the applet API that leaks sensitive information. Finally, the module generates a global data flow graph (GDFG).

[0020] Another object of the present invention is to provide a method for detecting privacy leakage of a small program based on an abstract syntax tree, comprising:

[0021] Decompilation module: Use the decompilation tool for applet to unpack the applet package in wxapkg format and restore the source code structure.

[0022] AST generation module: Use the Esprima library to convert JavaScript files into the JSON format of the abstract syntax tree (AST), and use the Graphviz library to generate a graphical format.

[0023] Dependency analysis module: By parsing the nodes and WXML tags of AST, the dependency relationships between modules are established and a global dependency graph is generated.

[0024] Control flow generation module: According to the division rules of Leaders and Terminators, the JavaScript source code is divided into multiple basic blocks, edges are established according to the type of boundaries, and GCFG is obtained by combining GDG.

[0025] Taint-pointer analysis module: By inputting GCFG, an algorithm that performs taint and pointer analysis simultaneously is used to obtain a complete privacy execution path.

[0026] Another object of the present invention is to provide a computer device, comprising a memory and a processor, wherein the memory stores a computer program, and when the computer program is executed by the processor, the processor executes the steps of the mini-program privacy leakage detection method based on the abstract syntax tree.

[0027] Another object of the present invention is to provide a computer-readable storage medium storing a computer program, which, when executed by a processor, enables the processor to perform the steps of the mini-program privacy leakage detection method by joint analysis of taints and pointers.

[0028] Another object of the present invention is to provide an information data processing terminal, which is used to implement the mini-program privacy leakage detection system for joint analysis of stains and pointers.

[0029] In combination with the above technical solutions and the technical problems solved, the advantages and positive effects of the technical solutions to be protected by the present invention are as follows:

[0030] First, the present invention discloses a method for detecting privacy leakage of mini programs by joint analysis of stains and pointers, which is used to detect whether there is privacy leakage in the mini program, and when there is leakage, the system will provide a complete and accurate privacy leakage path. It includes decompiling the WXAPKG file of the applet to obtain the source code file, extracting the page logic file path specified in the app.json file, and using the expression parsing library and the graphical library to convert all logic layer JavaScript files into AST json and pdf file formats; obtaining the call dependency graph between the page logic layer file and the tool file layer and the module level of the tool file layer itself according to the file reference relationship, and obtaining the field-level binding dependency graph of the page rendering layer and the page logic layer according to the data and event binding relationship between the page rendering layer and the page logic layer, and merging the above two to obtain a global dependency graph; dividing the JavaSript code into multiple basic blocks according to the control flow boundary division rules, and determining the edge type according to the boundary information to obtain the logic layer file control flow graph, and merging it with the page global dependency graph to obtain a global control flow graph; inputting the GCFG into the taint-pointer analysis module, executing the static analysis algorithm according to the predefined sink and source libraries and data flow propagation rules, and returning a complete and accurate privacy leakage path when sensitive information is leaked.

[0031] Second, the present invention discloses a method for detecting privacy leakage of small programs based on an abstract syntax tree, which can effectively detect whether there is privacy information leakage in small programs. When a leakage problem is detected, a complete privacy leakage path will be output. The following is a description of the advantages of each of the optimized technologies:

[0032] 1. A global control flow generation algorithm based on global dependencies is proposed, which can accurately and completely model the code execution logic between the page logic layer itself and the tool file layer and page rendering layer.

[0033] 2. A taint-pointer synchronization analysis algorithm for mini-programs is proposed. This algorithm can perform pointer analysis while performing taint analysis, effectively improving the efficiency and accuracy of analysis for large mini-programs, and at the same time achieving flow sensitivity based on GCFG.

[0034] Third, as auxiliary evidence of the inventiveness of the claims of the present invention, it is also reflected in the following important aspects:

[0035] (1) The expected benefits and commercial value of the technical solution of the present invention after transformation are:

[0036] The present invention can improve the security of mini-programs. By identifying and analyzing potential vulnerabilities and security risks in the code, it can effectively reduce the risk of malware attacks and protect user personal information and device security. This technology can help developers discover and solve security issues in the early stages of application development, thereby reducing the cost and time required to fix vulnerabilities later.

[0037] (2) The technical solution of the present invention fills the technical gap in the industry at home and abroad:

[0038] The present invention provides a method for detecting privacy leakage of small programs based on an abstract syntax tree. The existing static analysis method of small programs does not take into account that large small programs with ES6 syntax will contain the use of classes, which will result in low analysis accuracy. Traditional static analysis generally performs pointer analysis first and then taint analysis. The present invention implements an algorithm that performs taint and pointer analysis simultaneously by designing a specific algorithm, which can have a higher analysis efficiency even for large small programs. When the existing static analysis method of small programs performs control flow analysis on cross-module calls of small programs, there will be problems such as incomplete path coverage and insufficient processing of dependencies between modules, which limits the accurate modeling of the global execution logic of the small program. By designing a global control flow generation algorithm based on global dependencies, the present invention can accurately and completely model the code execution logic between the small program page logic layer itself and the tool file layer and the page rendering layer.

[0039] Fourth, technical problems of existing technologies:

[0040] The existing mini-app privacy leakage detection technology mainly faces the following technical problems:

[0041] 1. Accuracy Issues: Many existing methods rely on coarse static analysis techniques that may not accurately identify complex data flows and control flows, leading to false negatives and false positives.

[0042] 2. Efficiency issue: In-depth static analysis often requires a lot of computing resources and time, which is inefficient, especially when analyzing large applications.

[0043] 3. Insufficient flow sensitivity: Existing technologies often lose the execution order of some applet codes, which may lead to inaccurate analysis results.

[0044] In order to solve the above problems, the following technical solutions are proposed:

[0045] 1. Fine-grained code analysis:

[0046] -Decompile the WXAPKG file into a standard project structure format, and parse it into AST one by one according to the page logic layer file path declared in the app.json file to ensure the comprehensiveness and accuracy of the analysis.

[0047] 2. Complete control flow graph generation:

[0048] -Based on the global dependency graph, design a CFG generation algorithm for complex situations such as asynchronous calls of mini-programs, data and event binding of WXML tags and JavaScript, and declaration cycle usage, to comprehensively and accurately model the execution logic of the code.

[0049] 3. Advanced static analysis algorithms:

[0050] -The taint-pointer joint analysis module is based on AST and GCFG, and uses a synchronous analysis algorithm to perform program static analysis, which can accurately identify potential privacy leakage paths.

[0051] The implementation of this technical solution has brought about the following significant technological advances:

[0052] (1) Improve detection accuracy: Through fine-grained analysis and flow-sensitive static analysis, it can more accurately identify real privacy leakage issues and reduce false positives and negatives.

[0053] (2) Optimizing performance and efficiency: By combining taint and pointer analysis, the efficiency of the analysis is significantly improved, so that even large applications can be analyzed in a reasonable time.

[0054] (3) Enhanced application security: This method can identify and report complex privacy leakage paths, providing developers with powerful tools to enhance the security of their applications.

[0055] (4) Adapting to obfuscation analysis: Using AST as an intermediate form of static analysis, this tree structure provides the basic conditions for anti-obfuscation static analysis

[0056] The present invention provides an efficient and accurate method for detecting privacy leakage of small programs based on an abstract syntax tree, which can effectively solve the deficiencies of the prior art in terms of accuracy, efficiency and flow sensitivity. BRIEF DESCRIPTION OF THE DRAWINGS

[0057] Figure 1 It is a flow chart of a method for detecting privacy leakage of a small program based on an abstract syntax tree provided by an embodiment of the present invention.

[0058] Figure 2 It is a structural block diagram of a small program privacy leakage detection system based on an abstract syntax tree provided in an embodiment of the present invention.

[0059] Figure 3It is an overall framework diagram of a small program privacy leakage detection system based on an abstract syntax tree provided in an embodiment of the present invention. DETAILED DESCRIPTION

[0060] In order to make the purpose, technical solution and advantages of the present invention more clearly understood, the present invention is further described in detail below in conjunction with the embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.

[0061] like Figure 1 As shown, a method for detecting privacy leakage of a small program based on an abstract syntax tree provided by an embodiment of the present invention includes the following steps:

[0062] S101, decompile the WXAPKG file into a standard complete project structure;

[0063] S102, converting the page logic file specified in the app.json file, the tool function file in the utils directory, and the third-party SDK file into an abstract syntax tree JSON format representation, and calling a graphical library to generate a visual image format representation;

[0064] S103, establishing a global dependency graph according to the dependency generation rule, establishing a data and event binding dependency graph between the rendering layer and the page logic layer, and a call dependency graph between the tool function layer itself and the page logic layer, and merging the above to obtain a global dependency graph;

[0065] S104, based on the dependency graph, divide the mini-program code into multiple basic blocks according to the basic block division rules, establish edges between basic blocks according to the types of Terminators and Leaders, and merge the control flow graphs of all modules to obtain a global control flow graph.

[0066] S105, input the constructed GCFG into the taint-pointer analysis module for synchronous analysis algorithm, obtain the global data flow graph through the customized sink and source and data flow propagation rules, and return the complete privacy leakage path when there is a privacy leakage problem in the target applet.

[0067] In S101, the input WXAPKG file is decompiled to extract the standard applet source code and other complete files. The WXAPKG file is decompressed by using a decompilation tool to obtain the JavaScript code file of the logic layer, the WXML file of the rendering layer, the WXSS file of the style layer, and the configuration file, and the app.json file is parsed to extract the valid page file path, providing the target file for analysis for subsequent processing.

[0068] In S102, each JavaScript file in the logic layer is converted into an abstract syntax tree to provide a structured representation for subsequent analysis. The JavaScript file is parsed using the Esprima library, converted into the JSON format of AST, and a visual graphical representation of AST is generated using the Graphviz library to provide an intuitive code tree structure diagram.

[0069] In S103, the dependency relationship between each module in the mini program is analyzed and constructed. A data and event binding dependency graph between the rendering layer and the page logic layer, a call dependency graph between the tool function layer and the page logic layer, and a call dependency graph of the tool function layer itself are constructed, and the three are combined to obtain a global dependency graph.

[0070] In S104, the global control flow graph is generated based on the node analysis rules of the abstract syntax tree and the global dependency graph. The AST is traversed by using a depth-first traversal to divide the basic blocks of the control flow, generate a preliminary structure of the control flow graph, and obtain the global control flow graph based on the dependency relationship in the code.

[0071] In S105, the constructed GCFG is input into the static analysis module to execute the taint and pointer joint analysis algorithm. Two types of sources, taint source (TS) and pointer source (PS), are defined, corresponding to the acquisition of sensitive data and the introduction of new objects, respectively. According to the predefined data flow analysis rules, potential privacy leakage paths are identified to generate a global data flow graph.

[0072] like Figure 2 As shown, an embodiment of the present invention provides a method for detecting privacy leakage of a small program based on an abstract syntax tree, including:

[0073] Decompilation module: Use the decompilation tool for applet to unpack the applet package in wxapkg format and restore the source code structure.

[0074] AST generation module: Use the Esprima library to convert JavaScript files into the JSON format of the abstract syntax tree, and use the Graphviz library to generate a graphical format.

[0075] Dependency analysis module: By parsing the nodes and WXML tags of AST, the dependency relationships between modules are established and a global dependency graph is generated.

[0076] Control flow generation module: According to the division rules of Leaders and Terminators, the JavaScript source code is divided into multiple basic blocks, edges are established according to the type of boundaries, and GCFG is obtained by combining GDG.

[0077] Taint-pointer analysis module: By inputting GCFG, an algorithm that performs taint and pointer analysis simultaneously is used to obtain a complete privacy execution path.

[0078] Another object of the present invention is to provide a computer device, comprising a memory and a processor, wherein the memory stores a computer program, and when the computer program is executed by the processor, the processor executes the steps of the mini-program privacy leakage detection method based on the abstract syntax tree.

[0079] Another object of the present invention is to provide a computer-readable storage medium storing a computer program, which, when executed by a processor, enables the processor to execute the steps of the mini-program privacy leakage detection method based on an abstract syntax tree.

[0080] Another object of the present invention is to provide an information data processing terminal, which is used to implement the mini-program privacy leakage detection system based on the abstract syntax tree.

[0081] The present invention is specifically implemented:

[0082] The present invention provides a small program privacy leakage detection method based on abstract syntax tree, which solves the flow sensitivity and code coverage while improving the analysis efficiency and accuracy, and provides a basic condition for the static analysis of anti-obfuscation. Figure 3 , including the following steps:

[0083] Step 1: Decompile the wxapkg file of the applet to extract the standard applet source code and other complete project files.

[0084] Step 2: Convert each JavaScript file in the logic layer into an abstract syntax tree (AST) to provide a structured representation for subsequent analysis.

[0085] Step 3: Based on the extracted complete project files, analyze and build the global dependencies between the rendering layer and the logic layer, as well as between different logic layers in the applet.

[0086] Step 4: Perform node analysis on AST based on basic block generation rules, and build the global control flow graph of the applet in combination with the module dependency graph.

[0087] Step 5: Based on GCFG, according to the data flow analysis rules for the mini-program, execute the taint-pointer joint analysis algorithm to generate a global data flow graph.

[0088] In step one, the embodiment of the present invention provides that by decompiling the wxapkg file, the mini-program source code and other project files obtained include but are not limited to the JavaScript code of the logic layer, the WXML file of the rendering layer, the style sheet WXSS file and the configuration file.

[0089] In step 2 provided by the embodiment of the present invention, all valid page file paths are obtained from the app.json file, and a one-by-one traversal method is adopted to convert the Javascript files of each logical layer into the form of an abstract syntax tree using an expression parsing library.

[0090] In step three provided in the embodiment of the present invention, a global dependency graph is established according to the dependency generation rule, which mainly includes the following two graphs:

[0091] (1) Field-level dependency graph of data and event binding between the rendering layer and the page logic layer

[0092] The data binding dependency graph describes the dynamic data transfer relationship between the rendering layer (WXML) and the page logic layer (JavaScript), focusing on the dependency between the data binding fields in the rendering layer and the fields defined in the logic layer data. Use the WXML parser to extract the dynamic data binding fields in the rendering layer file, and bind the field variables therein to the fields in the page logic layer data object. Use the WXML parser to extract the event binding fields in the rendering layer file, and bind the event attributes and event processing function names to the function names in the page logic layer.

[0093] (2) Function-level dependency graph between the tool function layer and the logic layer

[0094] By parsing the nodes involving module calls in AST, including keywords such as import, require, and export, corresponding to nodes such as ImportDeclaration, CallExpression, and ExportNamedDeclaration, a reference relationship between functions is established.

[0095] Merge the above two sub-dependency graphs to obtain the global dependency graph.

[0096] In step 4 provided by the embodiment of the present invention, the AST is traversed using a depth-first traversal method. The first instruction of a basic block is defined as a Leader, indicating the beginning of a basic block, and the last instruction of a basic block is defined as a Terminator, indicating that it may jump to other basic blocks or end the program. The node information corresponding to Terminators and Leaders such as jumps, function calls, and loop controls is parsed, the range field of the node is extracted, and the range values ​​in adjacent range fields are subtracted to obtain a basic block.

[0097] In order to maintain the integrity of the context when traversing the AST, an element stack data structure is introduced, which is used to record the node path when traversing the AST. When traversing the AST, each time an AST node is visited, the current node is added to the stack, and the node is removed from the stack after the visit.

[0098] In order to adapt to the multi-entry execution characteristics of mini-programs, a comprehensive modeling of the code execution order of mini-programs is carried out, and a path-insensitive analysis scheme is adopted. Instead of considering each possible execution order separately, a comprehensive modeling method is used to incorporate different trigger points (such as life cycle functions, event processing functions, asynchronous task callbacks, etc.) into the same control flow model.

[0099] For subsequent data flow analysis based on GCFG and AST, each basic block needs to be bound to the corresponding AST node. The following algorithm is used:

[0100] 1. Convert the entire ast.json file into a dictionary, where the key is the ast node id and the value is the detailed node information.

[0101] 2. Traverse the AST and check the following conditions:

[0102] - Whether the range of the node is within the range of the basic block.

[0103] -Whether the node type belongs to the type related to data flow propagation (AssignmentExpression, CallExpression, etc.).

[0104] 3. Append the node IDs that meet the criteria to the basic block.

[0105] Finally, the nodes of the control flow graph are defined as basic blocks, the edges of the control flow graph are defined according to the node types corresponding to Terminators and Leaders, and the basic blocks and edges are connected to obtain the global control flow graph.

[0106] In step 5 provided by the embodiment of the present invention, the constructed GCFG is input into the taint-pointer analysis module to execute the taint and pointer joint analysis algorithm. To better illustrate and implement the algorithm, the source is broadly defined as two types: taint source (TS) and pointer source (PS). TS comes from the mini-program API that inputs and returns sensitive information from users, PS comes from the introduction of new objects, and the sink is the mini-program API that leaks sensitive information. The specific rules are defined as follows.

[0107] SourceAPI rules:

[0108] category API Name Location Information wx.getLocation Location Information wx.chooseLocation Location Information wx.onLocationChange Device Communication wx.getSystemInfo Device Communication wx.startBluetoothDevicesDiscovery Device Communication wx.writeBLECharacteristicValue Device Communication wx.sendHCEMessage Device Communication wx.sendSMS Local write operations wx.setStorage Local write operations wx.setStorageSync Local write operations wx.saveFile Local write operations wx.setClipboardData Open Interface wx.requestPayment Open Interface wx.shareAppMessage Open Interface wx.getWeRunData Open Interface wx.startSoterAuthentication Log and interface console.log Log and interface console.warn Log and interface console.error Log and interface wx.showToast Log and interface wx.showModal Log and interface wx.showActionSheet

[0109] SinkAPI rules:

[0110] category API Name Network Operations wx.request Network Operations wx.uploadFile Device Communication wx.startBluetoothDevicesDiscovery Device Communication wx.writeBLECharacteristicValue Device Communication wx.sendHCEMessage Device Communication wx.sendSMS Local write operations wx.setStorage Local write operations wx.setStorageSync Local write operations wx.saveFile Local write operations wx.setClipboardData Open Interface wx.requestPayment Open Interface wx.shareAppMessage Open Interface wx.getWeRunData Open Interface wx.startSoterAuthentication Log and interface console.log Log and interface console.warn Log and interface console.error Log and interface wx.showToast Log and interface wx.showModal Log and interface wx.showActionSheet

[0111] The algorithm process of pointer and taint synchronization is as follows:

[0112] (1) Initialization

[0113] The constructed virtual main function name and GCFG are used as input, the work list (WorkList, WL) is initialized to be empty, the pointer taint flow graph (Pointer-Taint-Flow Graph, PTFG) is initialized to be empty, and the reachable method list (Reachable Methods, RM) is initialized to be empty. The name of the input method is added to the RM, the statement is added to the S set, and the taint and pointer of the statement are initialized, and the construction of some data flow graph edges is implemented.

[0114] (2) Traverse WL and add new elements

[0115] Traverse the <variable, pointing information> pairs to be processed in WL, obtain the pointer-taint information (PT) that the variable has not yet pointed to by taking the difference set, point the variable to the PT, and add <all successor nodes of the variable, pointing information> to WL.

[0116] (3) Processing PT propagation of instance fields

[0117] The information of each object in the difference set is extracted, the data flow propagation involving the instance field is processed, and the edge between the variable and the instance field is established.

[0118] (4) PT propagation for instance method calls

[0119] For each statement involving instance methods in the S set, find the target method through the dispatch method. Point the this parameter of the target method to the new object, establish a call edge from the statement to the target method, and execute the data flow propagation function on the method. Establish a key-value relationship between each parameter in the statement and the parameter of the target method and add it to WL. Establish a key-value relationship between the return value of the target method and the Receiver and add it to WL.

[0120] After the above steps, a global data flow graph is finally generated, which can completely and accurately represent the privacy execution path of the mini program.

[0121] In addition, the present application also provides an abstract syntax tree-based mini-program privacy leakage detection system and system virtualization software, including interconnected microprocessors and memories, wherein the microprocessors are programmed or configured to execute the aforementioned abstract syntax tree-based mini-program privacy leakage detection method.

[0122] An embodiment of the present application also provides a storage medium, in which a computer program is stored. When the computer program is run on a computer, the computer is enabled to execute the above-mentioned small program privacy leakage detection method based on the abstract syntax tree.

[0123] An embodiment of the present application also provides a computer device, including a general-purpose memory and a processor, wherein the memory is electrically connected to the processor, a computer program is stored in the memory, and the processor is used to execute the above-mentioned small program privacy leakage detection method based on the abstract syntax tree by calling the computer program stored in the memory.

[0124] It should be noted that the method for detecting privacy leakage of small programs based on the abstract syntax tree adopted by the present invention realizes decompiling the WXAPKG file to obtain the complete source code file, converting the JavaScript file into the form of an abstract syntax tree using the expression parsing library, performing dependency analysis on the basis of this AST, obtaining the field-level and function-level dependencies between the tool function file, the page logic file, and the rendering layer file, obtaining the global control flow graph based on the division rules of Leaders and Terminators, and obtaining the global data flow graph based on the taint-pointer joint analysis algorithm and the sink&source library and data flow propagation analysis rules. The present invention can effectively ensure the code coverage while improving the operating efficiency and analysis accuracy, and at the same time provide the basic conditions for the static analysis of obfuscated code.

[0125] It should be noted that the embodiments of the present invention can be implemented by hardware, software or a combination of software and hardware. The hardware part can be implemented using dedicated logic: the software part can be stored in a memory and executed by an appropriate instruction execution system, such as a microprocessor or a dedicated design hardware. It can be understood by a person of ordinary skill in the art that the above-mentioned devices and methods can be implemented using computer executable instructions and / or contained in a processor control code, such as a carrier medium such as a disk, CD or DVD-ROM, a programmable memory such as a read-only memory (firmware), or a data carrier such as an optical or electronic signal carrier. Such code is provided on the carrier medium such as a disk, CD or DVD-ROM, a programmable memory such as a read-only memory (firmware), or a data carrier such as an optical or electronic signal carrier. The device and its modules of the present invention can be implemented by hardware circuits such as ultra-large-scale integrated circuits or gate arrays, semiconductors such as logic chips, transistors, etc., or programmable hardware devices such as field programmable gate arrays, programmable logic devices, etc., can also be implemented by software executed by various types of processors, and can also be implemented by a combination of the above-mentioned hardware circuits and software such as firmware.

[0126] 2. Application Examples: In order to prove the creativity and technical value of the technical solution of the present invention, this section provides application examples of the technical solution of the claims on specific products or related technologies.

[0127] The present invention randomly crawled 30 mini-programs through a crawler for experiment. First, the present invention obtained the packaged file format of the mini-program in the directory C:\Users\{system user name}\Documents\WeChat Files\Applet\{appid of the mini-program}\. Then the present invention decompiled the WXAPKG file of the target mini-program and restored it to the form of source code.

[0128] After obtaining the source code, the present invention extracts the valid page logic file directory in app.json and the tool function file in the utils directory, and converts them into a hierarchical tree code structure.

[0129] Then, by processing AST in a deep traversal manner, analyzing the node information at each level, extracting the data binding relationship, event binding relationship, and function call relationship, and establishing the dependency chain between each layer, we can obtain a global dependency graph between the tool function layer, page logic layer, and page rendering layer.

[0130] After obtaining the GDG, this graph is input into the control flow generation module, and the basic blocks of multiple mini-programs are obtained based on the division rules based on Leaders and Terminators. The type of control flow edge is determined according to the type of Leaders and Terminators, and each basic block is connected with an edge to obtain the global control flow graph.

[0131] Finally, the GCFG is input into the taint-pointer analysis module, which executes the algorithm of simultaneous taint and pointer analysis according to the sink and source libraries and the specific data flow propagation rules involved in the applet to obtain the global data flow graph.

[0132] 3. Evidence of the effects of the embodiments The embodiments of the present invention have achieved some positive effects during the development or use process, and indeed have great advantages over the prior art, which are described below in combination with actual conditions.

[0133] The present invention proposes a control flow generation algorithm based on global dependencies. The algorithm first extracts the global dependencies between the tool function layer, the page logic layer and the page rendering layer by parsing the abstract syntax tree of the code. Then, according to the division rules of Leaders and Terminators, the program is divided into multiple basic blocks, and the starting point and end point of each basic block are clarified. Finally, by connecting the control flow paths between basic blocks, a control flow graph covering global dependencies is generated, which effectively adapts to the execution characteristics of mini programs with multiple entries, across pages, across components, and across files.

[0134] The present invention proposes an analysis algorithm that combines taint analysis and pointer analysis. The algorithm performs the two analysis methods simultaneously, thereby avoiding the redundant calculations caused by the traditional method of "first pointer analysis and then taint analysis". Specifically, the method introduces pointer analysis information in real time during the taint analysis process without the need for repeated analysis. This method not only improves the efficiency of the analysis, but also can more accurately capture the flow of pointers and taint data in the program, thereby improving the accuracy and completeness of static analysis.

[0135] According to the experimental test results, the full process of automatic analysis of the decompilation module, AST generation module, dependency analysis module, control flow generation module, and taint-pointer analysis module can be effectively realized, and the analysis process and results can be output on the console. After testing, for multiple 8M applications, the accuracy of static analysis reached 92.5%, which is 9.3 percentage points higher than CodeQL's 83.2%, significantly improving the analysis accuracy.

[0136] The above description is only a specific implementation mode of the present invention, but the protection scope of the present invention is not limited thereto. Any modification, equivalent substitution and improvement made by any technician familiar with the technical field within the technical scope disclosed by the present invention and within the spirit and principle of the present invention should be covered by the protection scope of the present invention.

Claims

1. A method for detecting privacy leakage of small programs based on abstract syntax tree, characterized in that: The following steps are involved: Step 1: Decompile the wxapkg file of the applet to extract the standard applet source code and other complete project files. Step 2: Convert each JavaScript file in the logic layer into an abstract syntax tree to provide a structured representation for subsequent analysis. Step 3: Based on the complete project file and AST, analyze and build the global dependencies between the rendering layer and the logic layer, and between different logic layers in the applet. Step 4: Based on the basic block generation rules, perform node analysis on each AST, and build the global control flow graph of the applet in combination with the module dependency graph. Step 5: Based on GCFG, according to the data flow analysis rules for the mini-program, execute the taint-pointer joint analysis algorithm to generate a global data flow graph.

2. The method for detecting privacy leakage of small programs based on abstract syntax tree according to claim 1 is characterized in that: In step 1, the obtained applet source code and other project files include but are not limited to the JavaScript code of the logic layer, the WXML file of the rendering layer, the style sheet WXSS file and the configuration file.

3. The method for detecting privacy leakage of small programs based on abstract syntax tree according to claim 1 is characterized in that: In step 2, all valid page logic layer file paths are obtained from the app.json file, and each page logic and tool function layer file is traversed one by one, and the esprima library is used to convert it into an abstract syntax tree for each page logic and tool function layer file.

4. The method for detecting privacy leakage of small programs based on abstract syntax tree according to claim 1 is characterized in that: In step three, based on WXML tags and AST nodes, a data and event binding dependency graph between the rendering layer and the page logic layer, and a call dependency graph between the tool function layer itself and the logic layer are established, and the above two are merged to obtain a global dependency graph.

5. The method for detecting privacy leakage of small programs based on abstract syntax tree according to claim 1 is characterized in that: In step 4, the AST is traversed using a depth-first traversal method. Based on the designed control flow basic block boundary division rules, the boundaries of each basic block are obtained. The control flow generator divides the JavaScript source code into multiple basic blocks and generates the edges of the control flow graph according to the AST node type of the basic block boundary. The initial CFG structure can be generated with only one traversal. Each basic block represents a continuous piece of code logic, and the edges of the control flow graph describe the execution order and jump relationship between these basic blocks. Finally, the generator combines the dependencies in the code to build the global control flow graph of the applet.

6. The method for detecting privacy leakage of small programs based on abstract syntax tree according to claim 1 is characterized in that: In step 5, the constructed GCFG is input into the synchronization analysis module to execute the taint and pointer joint analysis algorithm. To better illustrate and implement the algorithm, the source is broadly defined as two types: taint source (TS) and pointer source (PS). TS comes from the user input and the applet API that returns sensitive information, PS comes from the introduction of new objects, and the sink is the applet API that leaks sensitive information. Finally, the module generates a global data flow graph (GDFG).

7. A small program privacy leakage detection system based on an abstract syntax tree that implements the small program privacy leakage detection method based on an abstract syntax tree as described in any one of claims 1 to 6, characterized in that: The applet privacy leakage detection system based on the abstract syntax tree includes: Decompile module, use the decompile tool for applet to unpack the applet package in wxapkg format and restore the source code structure. The AST generation module uses the Esprima library to convert JavaScript files into the JSON format of the abstract syntax tree (AST), and uses the Graphviz library to generate a graphical format. The dependency analysis module establishes the dependency relationships between modules by parsing the nodes and WXML tags of AST and generates a global dependency graph. The control flow generation module divides the JavaScript source code into multiple basic blocks according to the division rules of Leaders and Terminators, establishes edges according to the type of boundaries, and combines GDFG to obtain GCFG. The taint-pointer analysis module, by inputting GCFG to perform taint and pointer analysis simultaneously, obtains a complete privacy execution path.

8. A computer device, characterized in that: The computer device includes a memory and a processor, the memory stores a computer program, and when the computer program is executed by the processor, the processor executes the steps of the small program privacy leakage detection method based on the abstract syntax tree as described in any one of claims 1-6.

9. A computer-readable storage medium storing a computer program. When the computer program is executed by a processor, the processor executes the steps of the small program privacy leakage detection method based on an abstract syntax tree as described in any one of claims 1 to 6.

10. An information data processing terminal, characterized in that: The information data processing terminal is used to implement the mini-program privacy leakage detection system based on the abstract syntax tree as described in claim 7.

Citation Information

Cited By

  • Private data compliance auxiliary evaluation method and system based on large language model

    CN122065342A

  • Privacy data compliance auxiliary evaluation method and system based on large language model

    CN122065342B